Security, in plain language
Every call Ordo answers carries someone's name, plans, and phone number. Here is exactly how that information is protected · written for owners, not auditors. The legally binding versions live in our legal documents.
Your data is walled off from every other business
Each business on Ordo is a separate tenant. Your calls, customers, reservations, and transcripts are isolated at the database layer, beneath the application code · a query from one tenant physically cannot return another tenant's rows. Your regulars are never visible to the restaurant down the street, even though the same platform answers both phones.
Encrypted in transit and at rest
Call audio, transcripts, and account data are encrypted while moving and while stored, and operator dashboard sessions run over HTTPS with modern TLS. This applies to every account on every tier.
Callers are told, every time
Every Ordo call opens with a spoken disclosure: the caller is talking to an automated AI assistant, and the call may be recorded. This line is added in code · a business using Ordo cannot edit it out of their greeting. Nobody gets tricked into thinking they reached a person, and the recording notice satisfies Canadian consent expectations before the conversation starts.
No cards, ever, on the phone
Ordo never asks for a card number, CVV, or billing details on a call. Payment stays on your existing checkout, at your counter, or at your front desk. If a caller starts reading out a card number, the agent steers away · there is nothing in the pipeline built to capture it.
Your calls stay yours
Nothing about your calls is sold or shared with advertisers, and transcripts are never used to train shared AI models. Your calls exist to run your business: they power your dashboard, your customer memory, and nothing else. The website itself sets no tracking cookies · the Cookie Policy is the shortest document we publish.
Canadian company, Canadian privacy law
Ordo is operated from Ontario and built to comply with PIPEDA and Quebec Law 25. Requests to access or delete personal information get a response within 30 days, at no charge · that applies to your business's data and to a caller asking about their own call record. The full commitments are in the Privacy Policy.
Some data is processed in the United States
Ordo runs on infrastructure in Canada and the United States, and some of the providers that carry calls, transcribe them, and host the software operate in the US. While information is in the US it is subject to US law and can be accessed by US courts, law enforcement, and government authorities under lawful process, without notice to you. That is true of any company using US providers. Ordo limits the exposure by collecting little, encrypting everything in transit and at rest, and contractually holding each provider to using the data only to run the service. The countries and provider categories are listed in the Sub-Processors page.
Retention is written down
Not "as long as necessary" · actual windows, published in the Privacy Policy:
- Caller records (written transcripts and the details drawn from them · Ordo does not store call audio) · kept up to 24 months of account inactivity, then automatically deleted. Shorter windows available on request.
- Account data · life of the account plus 90 days for wind-down and export.
- Billing records · at least 7 years, as Canadian tax law requires.
- Server access logs · up to 12 months, for security investigation.
When something is deleted, it leaves active systems within 30 days and ages out of backups as rotations pass. Cancelling your account exports your data out, then erases it after a 30-day grace period.
The sensitive calls go to people
Allergies, medical symptoms, complaints, billing disputes · Ordo does not try to be clever with any of it. These route to a human with a short context summary, by rule. For future medical customers this posture goes further: no clinical advice of any kind, and US clinics will require a signed Business Associate Agreement before a single patient call flows · the DPA and BAA templates are part of the legal package.
What we don't have yet
Ordo is a pilot-stage product and has not completed a SOC 2 audit · we'd rather tell you that plainly than imply otherwise. What we publish instead is the practice itself: this page, the sub-processor list, written retention windows, and legal documents you can actually read. Certifications will come as the company grows into them.
A question this page doesn't answer?
Email privacy@useordo.org · a person reads it, and the answer usually lands within a business day.